Malicious PDF — malware analysis report

Static analysis result for SHA-256 e44887153fd61bbf…

MALICIOUS

PDF

17.7 KB Created: 2019-05-06 16:58:06 +01:00 Authoring application: mPDF 5.7
MD5: 9ac50fedde308b2a93d2773955373979 SHA-1: 7e5289da8ee4b70b7c5d396adaca94b2c99fa218 SHA-256: e44887153fd61bbf2528d59224f439ecb947b9415944b30c2f7179b3fe29425a
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a large number of embedded links, identified by the PDF_SEO_LINK_FARM heuristic. The ML classifier also flagged this PDF as malicious with high confidence. While the document body is unreadable, the presence of numerous links suggests a lure or distribution mechanism. The primary IOCs are the embedded URLs, which are likely used to redirect users to malicious sites or download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://loaminoo.linkpc.net/1096093090093099/Codename-Night-Witch-The-Girls-from-Alcyone-Book-3-by-Cary-Caffrey.pdf
    • http://loaminoo.linkpc.net/1091098098090099/Merchantman-The-Girls-from-Alcyone-1-5-by-Cary-Caffrey.pdf
    • http://loaminoo.linkpc.net/1091094098092094/The-Girls-From-Alcyone-The-Girls-from-Alcyone-1-by-Cary-Caffrey.pdf
    • http://loaminoo.linkpc.net/7092091093095094/Bring-on-the-Night-A-Solstice-At-Night-Valentine-s-Anthology-by-Brina-Cary.pdf
    • http://loaminoo.linkpc.net/9096093097092098/Codename-Summer-Codename-Rebellion-4-by-Cyndi-Friberg.pdf
    • http://loaminoo.linkpc.net/2090098096097097/The-Girls-Book-3-Even-More-Ways-To-Be-The-Best-At-Everything-Girls-Book-by-Tracey-Turner.pdf
    • http://loaminoo.linkpc.net/1096090091097099/Codename-Zero-The-Codename-Conspiracy-1-by-Chris-Rylander.pdf
    • http://loaminoo.linkpc.net/3092097096096095/Girls-Night-Out-Boys-Night-In-by-Jessica-Adams.pdf
    • http://loaminoo.linkpc.net/1092095094094099/Witch-The-Spell-Within-The-Witch-Series-Book-2-by-L-S-Gagnon.pdf
    • http://loaminoo.linkpc.net/9096093097091096/Codename-Chandler-Trilogy---Three-Complete-Novels-Codename-Chandler-1-3-by-J-A-Konrath.pdf
    • http://loaminoo.linkpc.net/7092091093094091/The-Surgeon-s-Dilemma-Wards-of-Avalon-Book-1-by-Brina-Cary.pdf
    • http://loaminoo.linkpc.net/1091091098092096097/Wicked-Girls-A-Novel-of-the-Salem-Witch-Trials-by-Stephanie-Hemphill.pdf
    • http://loaminoo.linkpc.net/3097094099092092/The-Worst-Witch-Saves-The-Day-Worst-Witch-Book-5-by-Jill-Murphy.pdf
    • http://loaminoo.linkpc.net/4091094098096093/Hometown-Girls-Reunion-Hometown-Girls-Series-Book-2-by-Tressa-Messenger.pdf
    • http://loaminoo.linkpc.net/1091099098097097090/A-Source-Book-of-Royal-Commissions-and-Other-Major-Governmental-Inquiries-in-Canadian-Education-1787-1978-by-Cary-F-Goulson.pdf
    • http://loaminoo.linkpc.net/4095095093095090/A-Witch-s-Guide-to-Familiars-A-Book-amp-Candle-Mystery-Book-5-by-Aubrey-Harper.pdf
    • http://loaminoo.linkpc.net/9094096096090099/Girls-Night-Out-Vol-1-by-Ira-Ozaki.pdf
    • http://loaminoo.linkpc.net/1090091098095095099/Rivers-of-London-Night-Witch-4-by-Ben-Aaronovitch.pdf
    • http://loaminoo.linkpc.net/2093094099090090/Night-of-the-Unicorn-The-Federal-Witch-5-by-T-S-Paul.pdf
    • http://loaminoo.linkpc.net/2090091097095097/Rivers-of-London-Night-Witch-by-Ben-Aaronovitch.pdf